PT-2025-46779 · WordPress · Sureforms
Published
2025-11-13
·
Updated
2026-04-07
·
CVE-2025-12536
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SureForms plugin for WordPress versions prior to 1.14.0
Description
The SureForms plugin for WordPress is susceptible to sensitive information disclosure in versions up to and including 1.13.1. This is a result of the
auth callback parameter being set to return true during the registration of the ' srfm email notification' post meta, which permits unauthenticated access to the metadata. Successful exploitation allows unauthenticated attackers to extract sensitive data, including email notification configurations. These configurations often contain vendor-provided CRM/help desk dropbox addresses, CC/BCC recipients, and notification templates that could be exploited to inject malicious data into downstream systems.Recommendations
Update the SureForms plugin to version 1.14.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sureforms